CVE Feed

    Dashboard / CVE

    6.1
    Medium

    CVE-2019-16197

    Last Modified: 21 Nov 2024

    In htdocs/societe/card.php in Dolibarr 10.0.1, the value of the User-Agent HTTP header is copied into the HTML document as plain text between tags, leading to XSS.

    Published: 16 Sept 2019
    7.1
    High

    CVE-2019-16170

    Last Modified: 21 Nov 2024

    An issue was discovered in GitLab Enterprise Edition 11.x and 12.x before 12.0.9, 12.1.x before 12.1.9, and 12.2.x before 12.2.5. It has Incorrect Access Control.

    Published: 16 Sept 2019
    9.8
    Critical

    CVE-2019-16057

    Last Modified: 6 Nov 2025

    The login_mgr.cgi script in D-Link DNS-320 through 2.05.B10 is vulnerable to remote command injection.

    Published: 16 Sept 2019
    7.5
    High

    CVE-2016-10956

    Last Modified: 21 Nov 2024

    The mail-masta plugin 1.0 for WordPress has local file inclusion in count_of_send.php and csvexport.php.

    Published: 16 Sept 2019
    9.8
    Critical

    CVE-2017-18634

    Last Modified: 21 Nov 2024

    The newspaper theme before 6.7.2 for WordPress has script injection via td_ads[header] to admin-ajax.php.

    Published: 16 Sept 2019
    5.9
    Medium

    CVE-2019-16370

    Last Modified: 21 Nov 2024

    The PGP signing plugin in Gradle before 6.0 relies on the SHA-1 algorithm, which might allow an attacker to replace an artifact with a different one that has the same SHA-1 message digest, a related issue to CVE-2005-4900.

    Published: 16 Sept 2019
    9.8
    Critical

    CVE-2019-13474

    Last Modified: 21 Nov 2024

    TELESTAR Bobs Rock Radio, Dabman D10, Dabman i30 Stereo, Imperial i110, Imperial i150, Imperial i200, Imperial i200-cd, Imperial i400, Imperial i450, Imperial i500-bt, and Imperial i600 TN81HH96-g102h-g102 devices have insufficient access control for the /set_dname, /mylogo, /LocalPlay, /irdevice.xml, /Sendkey, /setvol, /hotkeylist, /init, /playlogo.jpg, /stop, /exit, /back, and /playinfo commands.

    Published: 16 Sept 2019
    5.4
    Medium

    CVE-2019-16333

    Last Modified: 21 Nov 2024

    GetSimple CMS v3.3.15 has Persistent Cross-Site Scripting (XSS) in admin/theme-edit.php.

    Published: 15 Sept 2019
    4.8
    Medium

    CVE-2019-16334

    Last Modified: 21 Nov 2024

    In Bludit v3.9.2, there is a persistent XSS vulnerability in the Categories -> Add New Category -> Name field. NOTE: this may overlap CVE-2017-16636.

    Published: 15 Sept 2019
    6.1
    Medium

    CVE-2019-16332

    Last Modified: 21 Nov 2024

    In the api-bearer-auth plugin before 20190907 for WordPress, the server parameter is not correctly filtered in the swagger-config.yaml.php file, and it is possible to inject JavaScript code, aka XSS.

    Published: 15 Sept 2019
    5.3
    Medium

    CVE-2019-16320

    Last Modified: 21 Nov 2024

    Cobham Sea Tel v170 224521 through v194 225444 devices allow attackers to obtain potentially sensitive information, such as a vessel's latitude and longitude, via the public SNMP community.

    Published: 15 Sept 2019
    6.1
    Medium

    CVE-2019-16321

    Last Modified: 21 Nov 2024

    ScadaBR 1.0CE, and 1.1.x through 1.1.0-RC, has XSS via a request for a nonexistent resource, as demonstrated by the dwr/test/ PATH_INFO.

    Published: 15 Sept 2019
    9.8
    Critical

    CVE-2019-14540

    Last Modified: 21 Nov 2024

    A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to com.zaxxer.hikari.HikariConfig.

    Published: 15 Sept 2019
    9.8
    Critical

    CVE-2019-16335

    Last Modified: 21 Nov 2024

    A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to com.zaxxer.hikari.HikariDataSource. This is a different vulnerability than CVE-2019-14540.

    Published: 15 Sept 2019
    6.5
    Medium

    CVE-2019-11739

    Last Modified: 21 Nov 2024

    Encrypted S/MIME parts in a crafted multipart/alternative message can leak plaintext when included in a a HTML reply/forward. This vulnerability affects Thunderbird < 68.1 and Thunderbird < 60.9.

    Published: 15 Sept 2019
    8.8
    High

    CVE-2019-16317

    Last Modified: 21 Nov 2024

    In Pimcore before 5.7.1, an attacker with limited privileges can trigger execution of a .phar file via a phar:// URL in a filename parameter, because PHAR uploads are not blocked and are reachable within the phar://../../../../../../../../var/www/html/web/var/assets/ directory, a different vulnerability than CVE-2019-10867 and CVE-2019-16318.

    Published: 14 Sept 2019
    8.8
    High

    CVE-2019-16318

    Last Modified: 21 Nov 2024

    In Pimcore before 5.7.1, an attacker with limited privileges can bypass file-extension restrictions via a 256-character filename, as demonstrated by the failure of automatic renaming of .php to .php.txt for long filenames, a different vulnerability than CVE-2019-10867 and CVE-2019-16317.

    Published: 14 Sept 2019
    6.1
    Medium

    CVE-2019-16307

    Last Modified: 21 Nov 2024

    A Reflected Cross-Site Scripting (XSS) vulnerability in the webEx module in webExMeetingLogin.jsp and deleteWebExMeetingCheck.jsp in Fuji Xerox DocuShare through 7.0.0.C1.609 allows remote attackers to inject arbitrary web script or HTML via the handle parameter (webExMeetingLogin.jsp) and meetingKey parameter (deleteWebExMeetingCheck.jsp).

    Published: 14 Sept 2019
    7.8
    High

    CVE-2019-16294

    Last Modified: 21 Nov 2024

    SciLexer.dll in Scintilla in Notepad++ (x64) before 7.7 allows remote code execution or denial of service via Unicode characters in a crafted .ml file.

    Published: 14 Sept 2019
    9.8
    Critical

    CVE-2019-16309

    Last Modified: 21 Nov 2024

    FlameCMS 3.3.5 has SQL injection in account/login.php via accountName.

    Published: 14 Sept 2019
    5.4
    Medium

    CVE-2019-16310

    Last Modified: 21 Nov 2024

    NIUSHOP V1.11 has XSS via the index.php?s=/admin URI.

    Published: 14 Sept 2019
    8.8
    High

    CVE-2019-16311

    Last Modified: 21 Nov 2024

    NIUSHOP V1.11 has CSRF via search&#95;info to index.php.

    Published: 14 Sept 2019
    6.1
    Medium

    CVE-2019-16312

    Last Modified: 21 Nov 2024

    s-cms V3.0 has XSS in index.php?type=text via the S_id parameter.

    Published: 14 Sept 2019
    7.5
    High

    CVE-2019-16313

    Last Modified: 21 Nov 2024

    ifw8 Router ROM v4.31 allows credential disclosure by reading the action/usermanager.htm HTML source code.

    Published: 14 Sept 2019
    9.8
    Critical

    CVE-2019-16314

    Last Modified: 21 Nov 2024

    Indexhibit 2.1.5 allows a product reinstallation, with resultant remote code execution, via /ndxzstudio/install.php?p=2.

    Published: 14 Sept 2019
    8.8
    High

    CVE-2019-16305

    Last Modified: 21 Nov 2024

    In MobaXterm 11.1 and 12.1, the protocol handler is vulnerable to command injection. A crafted link can trigger a popup asking whether the user wants to run MobaXterm to handle the link. If accepted, another popup appears asking for further confirmation. If this is also accepted, command execution is achieved, as demonstrated by the MobaXterm://`calc` URI.

    Published: 14 Sept 2019
    6.1
    Medium

    CVE-2020-10959

    Last Modified: 21 Nov 2024

    resources/src/mediawiki.page.ready/ready.js in MediaWiki before 1.35 allows remote attackers to force a logout and external redirection via HTML content in a MediaWiki page.

    Published: 14 Sept 2019
    9.8
    Critical

    CVE-2019-16303

    Last Modified: 21 Nov 2024

    A class generated by the Generator in JHipster before 6.3.0 and JHipster Kotlin through 1.1.0 produces code that uses an insecure source of randomness (apache.commons.lang3 RandomStringUtils). This allows an attacker (if able to obtain their own password reset URL) to compute the value for all other password resets for other accounts, thus allowing privilege escalation or account takeover.

    Published: 13 Sept 2019
    10
    Critical

    CVE-2019-5485

    Last Modified: 21 Nov 2024

    NPM package gitlabhook version 0.0.17 is vulnerable to a Command Injection vulnerability. Arbitrary commands can be injected through the repository name.

    Published: 13 Sept 2019
    7.5
    High

    CVE-2019-5484

    Last Modified: 21 Nov 2024

    Bower before 1.8.8 has a path traversal vulnerability permitting file write in arbitrary locations via install command, which allows attackers to write arbitrary files when a malicious package is extracted.

    Published: 13 Sept 2019
    7.8
    High

    CVE-2019-11660

    Last Modified: 21 Nov 2024

    Privileges manipulation in Micro Focus Data Protector, versions 10.00, 10.01, 10.02, 10.03, 10.04, 10.10, 10.20, 10.30, 10.40. This vulnerability could be exploited by a low-privileged user to execute a custom binary with higher privileges.

    Published: 13 Sept 2019
    9.8
    Critical

    CVE-2019-13548

    Last Modified: 21 Nov 2024

    CODESYS V3 web server, all versions prior to 3.5.14.10, allows an attacker to send specially crafted http or https requests which could cause a stack overflow and create a denial-of-service condition or allow remote code execution.

    Published: 13 Sept 2019
    7.5
    High

    CVE-2019-13532

    Last Modified: 21 Nov 2024

    CODESYS V3 web server, all versions prior to 3.5.14.10, allows an attacker to send specially crafted http or https requests which may allow access to files outside the restricted working directory of the controller.

    Published: 13 Sept 2019
    7.2
    High

    CVE-2019-5315

    Last Modified: 21 Nov 2024

    A command injection vulnerability is present in the web management interface of ArubaOS that permits an authenticated user to execute arbitrary commands on the underlying operating system. A malicious administrator could use this ability to install backdoors or change system configuration in a way that would not be logged. This vulnerability only affects ArubaOS 8.x.

    Published: 13 Sept 2019
    6.1
    Medium

    CVE-2019-5314

    Last Modified: 21 Nov 2024

    Some web components in the ArubaOS software are vulnerable to HTTP Response splitting (CRLF injection) and Reflected XSS. An attacker would be able to accomplish this by sending certain URL parameters that would trigger this vulnerability.

    Published: 13 Sept 2019
    9.8
    Critical

    CVE-2018-7081

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability is present in network-listening components in some versions of ArubaOS. An attacker with the ability to transmit specially-crafted IP traffic to a mobility controller could exploit this vulnerability and cause a process crash or to execute arbitrary code within the underlying operating system with full system privileges. Such an attack could lead to complete system compromise. The ability to transmit traffic to an IP interface on the mobility controller is required to carry out an attack. The attack leverages the PAPI protocol (UDP port 8211). If the mobility controller is only bridging L2 traffic to an uplink and does not have an IP address that is accessible to the attacker, it cannot be attacked.

    Published: 13 Sept 2019
    4.3
    Medium

    CVE-2019-13919

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0 SP1). Some pages that should only be accessible by a privileged user can also be accessed by a non-privileged user. The security vulnerability could be exploited by an attacker with network access and valid credentials for the web interface. No user interaction is required. The vulnerability could allow an attacker to access information that he should not be able to read. The affected information does not include passwords. At the time of advisory publication no public exploitation of this security vulnerability was known.

    Published: 13 Sept 2019
    2.7
    Low

    CVE-2019-13922

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0 SP1). An attacker with administrative privileges can obtain the hash of a connected device's password. The security vulnerability could be exploited by an attacker with network access to the SINEMA Remote Connect Server and administrative privileges. At the time of advisory publication no public exploitation of this security vulnerability was known.

    Published: 13 Sept 2019
    9.6
    Critical

    CVE-2019-13923

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in IE/WSN-PA Link WirelessHART Gateway (All versions). The integrated configuration web server of the affected device could allow Cross-Site Scripting (XSS) attacks if unsuspecting users are tricked into accessing a malicious link. User interaction is required for a successful exploitation. The user must be logged into the web interface in order for the exploitation to succeed. At the stage of publishing this security advisory no public exploitation is known.

    Published: 13 Sept 2019
    7.5
    High

    CVE-2019-10937

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in SIMATIC TDC CP51M1 (All versions < V1.1.7). An attacker with network access to the device could cause a Denial-of-Service condition by sending a specially crafted UDP packet. The vulnerability affects the UDP communication of the device. The security vulnerability could be exploited without authentication. No user interaction is required to exploit this security vulnerability. Successful exploitation of the security vulnerability compromises availability of the targeted system. At the time of advisory publication no public exploitation of this security vulnerability was known.

    Published: 13 Sept 2019
    9.8
    Critical

    CVE-2019-13918

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0 SP1). The web interface has no means to prevent password guessing attacks. The vulnerability could be exploited by an attacker with network access to the vulnerable software, requiring no privileges and no user interaction. The vulnerability could allow full access to the web interface. At the time of advisory publication no public exploitation of this security vulnerability was known.

    Published: 13 Sept 2019
    4.3
    Medium

    CVE-2019-13920

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0 SP1). Some parts of the web application are not protected against Cross Site Request Forgery (CSRF) attacks. The security vulnerability could be exploited by an attacker that is able to trigger requests of a logged-in user to the application. The vulnerability could allow switching the connectivity state of a user or a device. At the time of advisory publication no public exploitation of this security vulnerability was known.

    Published: 13 Sept 2019
    8.8
    High

    CVE-2019-16293

    Last Modified: 21 Nov 2024

    The Create Discoveries feature of Open-AudIT before 3.2.0 allows an authenticated attacker to execute arbitrary OS commands via a crafted value for a URL field.

    Published: 13 Sept 2019
    9.8
    Critical

    CVE-2010-5333

    Last Modified: 21 Nov 2024

    The web server in Integard Pro and Home before 2.0.0.9037 and 2.2.x before 2.2.0.9037 has a buffer overflow via a long password in an administration login POST request, leading to arbitrary code execution. An SEH-overwrite buffer overflow already existed for the vulnerable software. This CVE is to track an alternate exploitation method, utilizing an EIP-overwrite buffer overflow.

    Published: 13 Sept 2019
    7.5
    High

    CVE-2019-16288

    Last Modified: 21 Nov 2024

    On Tenda N301 wireless routers, a long string in the wifiSSID parameter of a goform/setWifi POST request causes the device to crash.

    Published: 13 Sept 2019
    5.4
    Medium

    CVE-2019-16289

    Last Modified: 21 Nov 2024

    The insert-php (aka Woody ad snippets) plugin before 2.2.8 for WordPress allows authenticated XSS via the winp_item parameter.

    Published: 13 Sept 2019
    6.9
    Medium

    CVE-2019-3646

    Last Modified: 21 Nov 2024

    DLL Search Order Hijacking vulnerability in Microsoft Windows client in McAfee Total Protection (MTP) Free Antivirus Trial 16.0.R18 and earlier allows local users to execute arbitrary code via execution from a compromised folder placed by an attacker with administrator rights.

    Published: 13 Sept 2019
    6.5
    Medium

    CVE-2019-12922

    Last Modified: 21 Nov 2024

    A CSRF issue in phpMyAdmin 4.9.0.1 allows deletion of any server in the Setup page.

    Published: 13 Sept 2019
    9.6
    Critical

    CVE-2019-13364

    Last Modified: 21 Nov 2024

    admin.php?page=account_billing in Piwigo 2.9.5 has XSS via the vat&#95;number, billing&#95;name, company, or billing&#95;address parameter. This is exploitable via CSRF.

    Published: 13 Sept 2019
    9.6
    Critical

    CVE-2019-13363

    Last Modified: 21 Nov 2024

    admin.php?page=notification_by_mail in Piwigo 2.9.5 has XSS via the nbm&#95;send&#95;html&#95;mail, nbm&#95;send&#95;mail&#95;as, nbm&#95;send&#95;detailed&#95;content, nbm&#95;complementary&#95;mail&#95;content, nbm&#95;send&#95;recent&#95;post&#95;dates, or param&#95;submit parameter. This is exploitable via CSRF.

    Published: 13 Sept 2019